[Git][security-tracker-team/security-tracker][master] Reserve DLA-4675-1 for rlottie

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Thu Jul 9 13:31:41 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dfa7ac33 by Emilio Pozuelo Monfort at 2026-07-09T14:31:29+02:00
Reserve DLA-4675-1 for rlottie

- - - - -


2 changed files:

- data/CVE/list
- data/DLA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -24682,7 +24682,6 @@ CVE-2026-49837
 	NOTE: https://github.com/osrg/gobgp/security/advisories/GHSA-gjrg-jjr3-56cm
 CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source rlottie allow ...)
 	- rlottie 0.1+dfsg-3 (bug #1138916)
-	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/589
 	NOTE: https://github.com/Samsung/rlottie/commit/ffe60942892c3d68b14560761ea920d360ef51bb
 	NOTE: Addressed by earlier Debian-specific patch Avoid-assertion-failures.patch (see #1138916)
@@ -24798,25 +24797,21 @@ CVE-2026-47320 (Access of uninitialized pointer, Uncontrolled Recursion vulnerab
 	- rlottie 0.1+dfsg-5 (bug #1138920)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	[bookworm] - rlottie <no-dsa> (Minor issue)
-	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/593
 	NOTE: https://github.com/Samsung/rlottie/commit/bf689b72b8482c5ea674235854bd11b6d1b42588
 CVE-2026-47319 (Memory allocation with excessive size value vulnerability in Samsung O ...)
 	- rlottie 0.1+dfsg-5 (bug #1138919)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	[bookworm] - rlottie <no-dsa> (Minor issue)
-	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/588
 	NOTE: https://github.com/Samsung/rlottie/commit/5def9f402b1cb5b09f52655e414f0afba4ffd959
 CVE-2026-47318 (Stack-based buffer overflow vulnerability in Samsung Open Source rlott ...)
 	- rlottie 0.1+dfsg-3 (bug #1138918)
-	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/582
 	NOTE: https://github.com/Samsung/rlottie/commit/9e4f354f6ebdf294738ef7abf1728f40889c2c51
 	NOTE: Addressed by earlier Debian-specific patch Fortify-FreeType-raster.patch (see #1138916)
 CVE-2026-47306 (Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...)
 	- rlottie 0.1+dfsg-3 (bug #1138917)
-	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/585
 	NOTE: https://github.com/Samsung/rlottie/commit/1cda06022e53206c230fb0c6e38b2adaea729a5d
 	NOTE: Addressed by earlier Debian-specific patch No-cyclic-structures.patch (see #1138916)
@@ -25016,7 +25011,6 @@ CVE-2026-10305 (Out-of-bounds read vulnerability in Samsung Open Source rlottie
 	- rlottie 0.1+dfsg-5 (bug #1139179)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	[bookworm] - rlottie <no-dsa> (Minor issue)
-	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/587
 	NOTE: https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77
 CVE-2025-71316 (SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[09 Jul 2026] DLA-4675-1 rlottie - security update
+	{CVE-2026-8916 CVE-2026-10305 CVE-2026-47306 CVE-2026-47318 CVE-2026-47319 CVE-2026-47320}
+	[bullseye] - rlottie 0.1+dfsg-2+deb11u2
 [09 Jul 2026] DLA-4674-1 chromium - security update
 	[bookworm] - chromium 150.0.7871.100-1~deb12u1
 [08 Jul 2026] DLA-4673-1 dpkg - security update



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dfa7ac330d3cc4ea61829f9008952b8c72375eac

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dfa7ac330d3cc4ea61829f9008952b8c72375eac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260709/7e1ea375/attachment.htm>


More information about the debian-security-tracker-commits mailing list